Unresolved Staff Comments
−Removed: Not Applicable
Cybersecurity
−Removed: Cybersecurity Risk Management and Strategy
−Removed: Our Company has a dedicated
−Removed: internal IT department with cybersecurity engineers who oversee various aspects of cybersecurity.
−Removed: These engineers specialize in different
−Removed: areas, including ensuring security during product development, particularly in the domains of cloud management platforms and network interactions,
−Removed: as well as managing cybersecurity for daily office communications.
−Removed: In the event of an unexpected
−Removed: cybersecurity incident, the engineers immediately report to the Company’s management.
−Removed: They are equipped with pre-established response
−Removed: plans to address such situations effectively and mitigate potential risks.
−Removed: Currently, our cybersecurity
−Removed: risk management relies primarily on internal resources.
−Removed: However, as the Company continues to expand, we anticipate engaging third-party
−Removed: consultants to assist in enhancing our cybersecurity management processes and addressing evolving threats.
−Removed: While we do not currently
−Removed: have third-party collaborations, the Company plans to implement a process for selecting and evaluating third-party service providers in
−Removed: This will include comparing services, signing security agreements, and having our internal engineers assess the third parties’
−Removed: achievement of security objectives.
−Removed: In the past three years,
−Removed: our Company has not experienced any material cybersecurity risks.
−Removed: To ensure robust protection against potential threats, we have implemented
−Removed: the following security measures:
+Added: Cybersecurity
+Added: Risk Management and Strategy
+Added: Company has a dedicated internal IT department with cybersecurity engineers who oversee various aspects of cybersecurity.
+Added: These engineers
+Added: specialize in different areas, including ensuring security during product development, particularly in the domains of cloud management
+Added: platforms and network interactions, as well as managing cybersecurity for daily office communications.
+Added: the event of an unexpected cybersecurity incident, the engineers immediately report to the Company’s management.
+Added: They are equipped
+Added: with pre-established response plans to address such situations effectively and mitigate potential risks.
+Added: our cybersecurity risk management relies primarily on internal resources.
+Added: However, as the Company continues to expand, we anticipate
+Added: engaging third-party consultants to assist in enhancing our cybersecurity management processes and addressing evolving threats.
+Added: we do not currently have third-party collaborations, the Company plans to implement a process for selecting and evaluating third-party
+Added: service providers in the future.
+Added: This will include comparing services, signing security agreements, and having our internal engineers
+Added: assess the third parties’ achievement of security objectives.
+Added: the past three years, our Company has not experienced any material cybersecurity risks.
+Added: To ensure robust protection against potential
+Added: threats, we have implemented the following security measures:
updating and changing critical passwords.
6 unchanged sentences
routine security training and awareness programs for employees.
−Removed: Cybersecurity Governance
−Removed: Currently, the Company’s
−Removed: board of directors does not oversee cybersecurity risks directly.
−Removed: However, plans are in place to introduce such oversight in the future.
−Removed: The Audit Committee of the Board will assume responsibility for cybersecurity risk oversight, with a plan to review cybersecurity matters
−Removed: on a quarterly basis.
−Removed: This initiative will ensure that the Company maintains robust oversight mechanisms to address evolving cybersecurity
−Removed: threats effectively.
−Removed: The responsibility for assessing
−Removed: and managing cybersecurity risks within the Company lies with the managers of the R&D department and the IT department.
−Removed: Both individuals
−Removed: possess relevant expertise in their respective fields, ensuring a high level of competence in identifying and mitigating cybersecurity
−Removed: Their duties include monitoring potential threats, implementing security protocols, and responding to incidents to safeguard company
−Removed: assets and operations.
−Removed: In the event of cybersecurity
−Removed: incidents or abnormal alerts, the relevant department managers immediately intervene and manage the situation.
−Removed: All logs and records related
−Removed: to such events are preserved for future analysis.
−Removed: Cybersecurity testing is incorporated into every stage of product development, ensuring
−Removed: that vulnerabilities are identified and addressed proactively.
−Removed: Additionally, server security patches are regularly updated to mitigate
−Removed: potential threats.
+Added: Cybersecurity
+Added: the Company’s board of directors does not oversee cybersecurity risks directly.
+Added: However, plans are in place to introduce such oversight
+Added: in the future.
+Added: The Audit Committee of the Board will assume responsibility for cybersecurity risk oversight, with a plan to review cybersecurity
+Added: matters on a quarterly basis.
+Added: This initiative will ensure that the Company maintains robust oversight mechanisms to address evolving
+Added: cybersecurity threats effectively.
+Added: responsibility for assessing and managing cybersecurity risks within the Company lies with the managers of the R&D department and
+Added: the IT department.
+Added: Both individuals possess relevant expertise in their respective fields, ensuring a high level of competence in identifying
+Added: and mitigating cybersecurity risks.
+Added: Their duties include monitoring potential threats, implementing security protocols, and responding
+Added: to incidents to safeguard company assets and operations.
+Added: the event of cybersecurity incidents or abnormal alerts, the relevant department managers immediately intervene and manage the situation.
+Added: All logs and records related to such events are preserved for future analysis.
+Added: Cybersecurity testing is incorporated into every stage
+Added: of product development, ensuring that vulnerabilities are identified and addressed proactively.
+Added: Additionally, server security patches
+Added: are regularly updated to mitigate potential threats.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.